Explainers

Call recording and GDPR: lawful basis, notice and retention

What the GDPR asks of a business that records calls. It covers the lawful basis, notice before recording starts, fixed retention, tight access and the national rules to check.

Cover for a guide to call recording under the GDPR, covering lawful basis, caller notice and retention

A contact centre has just switched on recording in its cloud PBX. Sales wants every call kept as cover. The quality team wants to replay conversations. IT is already asking where the files will live and who'll answer for them. The setting takes a minute to change, and the compliance work behind it takes a good deal longer.

This guide is for the IT leads, telecom integrators and operations managers who own that decision. Call recording under the GDPR counts as processing personal data. It needs a stated purpose and a lawful basis. The people on the line have to be told, and the audio can only live for a set time. A cloud PBX can automate a good share of those safeguards. The legal analysis, the internal governance and the business decision stay with you.

What call recording under the GDPR covers

A recorded call holds the caller's voice and number, the employee's voice, the time of the call and everything either person said. All of it is personal data about both people, so the GDPR (Regulation (EU) 2016/679) applies from the moment the file exists.

A second layer sits on top. The ePrivacy Directive (2002/58/EC) protects the confidentiality of communications, and its Article 5(2) allows recording "in the course of lawful business practice" to provide evidence of a commercial transaction or of another business communication. Each member state writes that directive into its own telecoms law, so the national rules later in this guide carry real weight.

Under the GDPR itself, you'll need a lawful basis from Article 6 before the first call is captured. Article 5 adds purpose limitation, data minimisation and storage limitation. Article 13 sets out what people must be told when their data is collected, and Article 32 asks for security that fits the risk. A recording feature that you switch on without those answers is already out of step with the regulation, however good the audio sounds.

Why recording every call adds risk

Recording everything looks like the safe option. It promises a complete trail, simpler checks and something to point to in a dispute. The GDPR's data minimisation principle pulls the other way, because you may only process what your stated purpose needs.

Take a contact centre that records every queue, every extension and every internal call. It has extended the processing to conversations that have no use for training, for dispute handling or for proving a sale. The system now captures far more than the purpose justifies, and each extra file is one more you'll have to defend in an audit.

Purpose comes before configuration

The first decision has nothing to do with audio formats or storage capacity. It's the reason a given call gets recorded at all. A serious policy separates the uses:

  • Training and coaching, working from a selection of relevant calls.

  • Quality monitoring, limited to representative interactions and tied to a documented objective.

  • Proof of a transaction, covering only the part of the call where a contract is concluded by phone.

  • Dispute handling, with restricted access and controlled retention.

Splitting the uses this way keeps technical availability apart from legal necessity. It also gives an integrator something concrete to configure. They can target a queue, a user group or a call direction and leave the rest of the phone system alone.

Recording stays off by default and switches on only for a documented purpose, scope and retention period.

Proportionality is the most useful day-to-day filter. A company may need to replay certain training calls without keeping personal conversations or internal chatter. A sales team may want proof of a phone sale without archiving the whole prospecting phase that led up to it.

Unlimited storage multiplies the exposure

Keeping every recording grows the volume of accessible data. It raises the security burden and makes each request from a data subject harder to answer. Audits get slower too, because you have to explain why each file still exists and who can open it.

A leaked audio file is one risk. A second risk is processing that was badly defined, too broad or impossible to purge cleanly. An IT team that starts from a purpose matrix can end with technical rules that block unjustified global activation.

Choosing a lawful basis under Article 6

The lawful basis decides which rights your callers have, and so it decides what your announcement has to say. The GDPR offers six bases. Four of them come up regularly in call recording.

Legal obligation applies when a law requires the recording. The clearest EU example is MiFID II. Investment firms must record telephone conversations relating to client orders and keep them for five years, or up to seven where the regulator asks. If your sector carries a rule like this, the obligation is your basis and the retention period comes with it.

Contract or legitimate interests usually covers proof of a transaction, read alongside the ePrivacy exception for evidence of commercial dealings. The recording has to stay close to that purpose. Recording the offer, the acceptance and the key terms fits. Recording the small talk before them is harder to justify.

Legitimate interests is the usual basis for quality monitoring and training. It needs a documented balancing test (a legitimate interests assessment) that weighs your need against the caller's and the employee's expectations. When you rely on it, people have a right to object under Article 21, and your notice must say so.

Consent looks simple but is fragile. Between employer and employee, supervisory authorities treat consent as rarely free, because of the imbalance of power, so staff recording seldom rests on it. For external callers, consent must be freely given and withdrawable. In practice that means offering a real way to decline, such as a key press that routes the call to an unrecorded line. If you can't offer that, consent is the wrong basis.

Many companies use more than one basis at once, one per purpose. That's fine as long as each queue or flow maps to exactly one purpose and one basis in your records.

Tell people before the recording starts

The announcement has to play at the start of the call, before any audio is captured. Article 13 lists what people must be told: who the controller is, the purpose, the lawful basis, how long the data is kept, the rights that apply, and the contact details of your data protection officer if you have one.

Nobody will sit through all of that on hold, so most organisations use a layered notice. A short spoken line gives the purpose and the basic rights and says where to find the rest. Your privacy notice on the website then carries the full detail. In a cloud PBX the short line fits into the call flow itself, through an announcement on the queue or a step in the cloud IVR menu. That makes the notice a rule you can check in the configuration, and you can prove it played.

Both groups need covering: the external callers and your own employees. Staff should receive their own written information before monitoring begins, separate from the caller announcement. In several countries their representatives must also be involved, as the next section shows.

National rules in Luxembourg, Belgium, Ireland and the Netherlands

The GDPR sets the common floor. Telecoms and employment law add rules that vary by country, and so does the exposure when something goes wrong. Treat the points below as a starting map, and confirm them with counsel for your sector.

  • Luxembourg. The National Commission for Data Protection (CNPD) supervises. The 2005 law on privacy in electronic communications transposes the ePrivacy Directive, including the exception for recording that proves a commercial transaction. Monitoring employees falls under the Labour Code (Article L.261-1), which requires prior information to staff and to the staff delegation.

  • Belgium. The Data Protection Authority supervises. The Electronic Communications Act of 13 June 2005 carries the ePrivacy exception for recording that proves a commercial transaction, and the parties must be told beforehand. The Criminal Code separately punishes intercepting communications that you aren't a party to.

  • Ireland. The Data Protection Commission supervises and has published guidance on call recording, which you should read before writing your announcement. The ePrivacy Regulations (S.I. 336 of 2011) transpose the directive. The Interception Act of 1993 treats interception without the consent of a party to the call as an offence.

  • Netherlands. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) supervises. Under Article 27 of the Works Councils Act, a system that can monitor staff needs the works council's consent before it goes live, and call recording normally counts as one.

Penalties differ too. GDPR fines are harmonised in their maximums. Criminal exposure for unlawful interception depends on the member state, so a group running queues in several countries should check each one.

Different uses, different rules

Proof of a contract concluded by phone is a narrow purpose. Only the part of the conversation that concludes the contract belongs in the file. The rest of the sales journey stays out, even when it happens on the same call.

A configuration you can audit includes:

  • Targeted triggering, tied to the queue, the extension or the call direction.

  • An announcement at the start of the call that the caller can understand.

  • Automatic retention, with deletion when the set period ends.

  • Limited access rights, granted by role.

  • An audit trail showing who played, exported or deleted a file.

Two more GDPR duties apply before launch. Article 30 requires an entry in your record of processing activities. Article 35 requires a data protection impact assessment where the processing is likely to be high risk, and systematic monitoring of employees or recording of sensitive conversations often meets that bar. A cloud PBX can enforce these controls once the purpose, retention and permission rules are settled.

Three business cases and the controls each needs

A customer disputes what an agent told them on an earlier call. Without a recording, the team leader rebuilds the timeline from the agent's notes, the CRM and the team's memory. With a targeted policy, they replay the call in question and check what was promised. The file can then be used as evidence, and a short extract can train the next hire. When the recording links to the customer record through computer telephony integration, the right call takes seconds to find.

The sensible scope is rarely the whole switchboard. A support queue, a few supervision extensions or selected calls usually cover the need. Internal calls, personal calls and flows unrelated to the purpose stay out of scope. A cloud PBX makes that selection easier because the routing rule, the announcement and the retention period sit in one call flow.

Healthcare needs the tightest set-up. Health data is special category data under Article 9 of the GDPR, which adds conditions on top of the Article 6 basis. An appointment line might keep a trace of a complex administrative request without recording clinical details in bulk. Before activation, the team defines the flow, the people allowed to listen and the process for access requests.

For a sales team, recording can help prove a contract concluded by phone. Retention stays limited to the exchanges tied to that conclusion. The fact that a few calls have evidential value doesn't justify archiving the whole prospecting pipeline.

Business useRecommended scopeMain safeguard
Customer serviceSupport queue or selected callsNotice, limited access and call selection
HealthcareA precisely defined administrative flowArticle 9 conditions and extra protection for health data
Phone salesThe exchange that concludes the contractNarrow purpose and controlled retention

The same logic holds for an integrator rolling out a phone system across several sites or clients. Each client may pursue a different purpose. A single policy for every user creates access nobody needs and makes the processing harder to justify.

A working set-up combines the spoken announcement, selective activation, an access log and automatic purging. The value comes from how well those rules are written and how consistently they run.

Securing audio files end to end

Flow of a call recording from encrypted voice transport through storage and logged playback to automatic purge

An audio file is sensitive from the second it's created. Security starts with voice transport and continues through writing the file, storing it, playback, export and deletion. It doesn't wait for a supervisor to download a recording.

That means an integrator reviews the whole chain, beyond the admin console. SIP over TLS protects the signalling, which carries who called whom and when. The audio itself travels separately and needs SRTP to be encrypted in transit. WebRTC calls in the browser use DTLS-SRTP by design. Ask your provider which of these it applies to desk phones, softphones and trunks, because TLS on the signalling leaves the voice stream untouched.

Access control by role

Authentication has to tell apart the agent who replays their own call, the manager who supervises a team and the administrator who sets the policy. One blanket permission for every manager quickly turns the recording store into a library anyone can browse without a reason.

Sound governance includes:

  1. Role-based control, with rights matched to the job.

  2. Action logging, especially for playback, download and deletion.

  3. Encryption at rest, which limits exposure if someone reaches the storage without authorisation.

  4. Separate environments for administration, daily operations and authorised archiving.

  5. A revocation procedure that runs as soon as someone changes role or leaves.

Automated retention and purge

The GDPR sets no fixed retention period for recordings. It asks you to keep them no longer than the purpose needs, and that period should appear in your records. A period written into an internal policy only works if the system enforces it. Otherwise files pile up and IT depends on a fragile manual clean-up.

Each flow gets an authorised duration and a controlled purge when it ends. Evaluation notes and scoring sheets can follow a different schedule from the audio, because they serve a different use. When a dispute requires you to keep a file longer, record the exception with a named owner and a review date.

Access and erasure requests under Articles 15 and 17 need a defined route. Your team should be able to find the file, check the scope of the request, log the decision and act on it without disrupting the service. A system that supports that route is one you can administer. A folder of audio files isn't.

EU hosting and where recordings live

Comparison of an on-site PBX and a European Union hosted cloud for infrastructure, security, updates, data location and IT load

Hosting rarely comes up in the first telephony workshops. The discussion covers queues, handsets and routing. Later someone finds that the metadata and audio files sit on infrastructure whose location, subprocessors and access rules nobody checked.

An on-site PBX gives you direct control of the servers. It also hands you physical security, backups, patching, monitoring and recovery. A small or mid-sized company can carry that load if it has the skills, procedures and staff. The trade-offs are set out in our guide to the IP PBX and when to keep it on site.

A cloud hosted outside the European Union raises a different set of questions. Chapter V of the GDPR governs transfers to third countries, and you'll need to assess the subprocessors and any foreign laws that could reach the data. For healthcare providers, local authorities and public services, that assessment can decide the contract.

CriterionOn siteEU-hosted cloud
InfrastructureBought and run by the companyRun by the provider
Physical securityOrganised at each siteHandled in the provider's data centres
UpdatesPlanned and applied in-houseIncluded in the service, per contract
Data locationDepends on the chosen architectureTo be checked with the provider and in the contract
Load on ITHeavy operational responsibilityShared, documented responsibilities

EU hosting doesn't make processing compliant on its own. It does make data sovereignty much easier to demonstrate when calls, recordings and metadata stay inside the European Union, backed by contractual and technical guarantees you can verify.

Server location is one question among several. Ask who administers the infrastructure and how access is logged. Ask where backups live, which data passes through third-party services, and how the provider handles deletion requests. The answers belong in the processor agreement that Article 28 requires.

Voxbi is a cloud phone system hosted in the European Union, with calls, recordings and metadata kept on EU infrastructure. How it fits alongside other options is covered in our cloud PBX guide. SaaS removes the hardware and update burden. It also means you do due diligence on the provider. The contracts, data centres, subprocessors and exit terms should be clear to your IT team and to the end client.

Rolling out a compliant recording policy

Six numbered steps for rolling out a compliant call recording policy, from defining the need to training users

The rollout starts in the record of processing, well before anyone touches the recording switch. The business owner describes the purpose, the lawful basis, the flows involved, the categories of people, the recipients and the retention period. IT then checks that the PBX can enforce those choices and that no rushed administrator can switch on global recording.

  1. Define the business need. Keep training, quality monitoring, dispute handling and proof of sale as separate purposes, each with its own lawful basis.

  2. Set the call scope. Configure queues, extensions, groups and call directions one by one. Internal and personal calls stay out when they have no link to the documented need.

  3. Prepare the notice. The opening announcement gives the purpose and the rights that match your basis, and it points to the full privacy notice. Staff get their own information beforehand, and in Luxembourg or the Netherlands their representatives are involved too.

  4. Configure retention. Automatic purging matches the period in your records. Audio files and evaluation notes run on separate schedules.

  5. Lock down permissions. Test roles, access logs, encryption and exports before the service opens.

  6. Train the users. An agent should know how to pause recording when the call drifts outside its purpose. A supervisor should know that every download creates a copy that also has to be governed.

Voxbi's call recording feature supports this approach once the targeting, access and retention rules are set before go-live. The integrator still validates the architecture with the client, documents who's responsible for what and checks any sector-specific requirements.

A limited pilot lets you test the announcements, permissions, audio quality, exports and purging without exposing the whole organisation. At the end of it, integrators and telecom resellers can hand the client a configuration file listing the purposes, the extensions involved, the owners and the procedures for data subject requests.

Compliance also depends on regular review. A new queue, team, provider or purpose can leave a configuration that used to be sound out of date. Book the review into your calendar the day the policy goes live.


Voxbi provides a cloud phone system hosted in the European Union, with call recording that you scope, restrict and purge by policy. To check the set-up against your own call flows with an integrator, write to hello@voxbi.com.

See Voxbi in your business.

Talk to us or to a certified Voxbi partner.